Trojan

MSIL/TrojanDownloader.Agent.JRU removal tips

Malware Removal

The MSIL/TrojanDownloader.Agent.JRU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.JRU virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL/TrojanDownloader.Agent.JRU?


File Info:

name: A61A9106F6CAB75FDF54.mlw
path: /opt/CAPEv2/storage/binaries/b32d999cd66cbdc58fdd9998b391b9f71a32286e39ae0e0d273f0444eedea28f
crc32: EE06DD5C
md5: a61a9106f6cab75fdf54ad246cbea0f2
sha1: 13b4eb4d448d0ab555769eca49eb240850137f46
sha256: b32d999cd66cbdc58fdd9998b391b9f71a32286e39ae0e0d273f0444eedea28f
sha512: cc36c0afa7061e954431ec26df56fa9bc4c14382339e8a51cb6c15e2fbc3ba66dd654e4658e4df98172863b3bdf3f4e14eb96cf672326df4fc2ce5531bd58504
ssdeep: 768:m1PgMx2wNRp/gbOSAHzCvV0eLmP1CD5LJ/31xiy1av/mcRzZ9jPIbgmIfgSIDZ:mLibJ/3Diyy/mucbgmIonZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18233A71577F96B13F2BE5BFA547A0120477BB46A5A32E70C0ECA60EF46977008A54F23
sha3_384: 99361b38e6d31786f8ae2a7963bf0eae636372f4366ea9acd545b1459d23564c8ba71ab9da3ecf6b0d781c858e420569
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-10-26 20:52:37

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: SotC Viewer
FileVersion: 0.0.0.0
InternalName: SotC Viewer.exe
LegalCopyright: Copyright © 2014
LegalTrademarks:
OriginalFilename: SotC Viewer.exe
ProductName: SotC Viewer
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/TrojanDownloader.Agent.JRU also known as:

CynetMalicious (score: 99)
ALYacTrojan.GenericKD.38063828
CylanceUnsafe
SangforExploit.MSIL.Shellcode.gen
AlibabaExploit:MSIL/Shellcode.f15f84b9
K7GWTrojan-Downloader ( 0058ba781 )
K7AntiVirusTrojan-Downloader ( 0058ba781 )
SymantecMSIL.Downloader!gen8
ESET-NOD32MSIL/TrojanDownloader.Agent.JRU
APEXMalicious
KasperskyHEUR:Exploit.MSIL.Shellcode.gen
BitDefenderTrojan.GenericKD.38063828
ViRobotTrojan.Win32.Z.Shellcode.53248
MicroWorld-eScanTrojan.GenericKD.38063828
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.38063828
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.ykewp
ZillyaExploit.Shellcode.Win32.18
TrendMicroTROJ_GEN.R06BC0PKM21
McAfee-GW-EditionRDN/Generic Exploit
FireEyeTrojan.GenericKD.38063828
EmsisoftTrojan.GenericKD.38063828 (B)
IkarusTrojan-Downloader.MSIL.Agent
GDataTrojan.GenericKD.38063828
JiangminExploit.MSIL.aay
AviraTR/Redcap.ykewp
Antiy-AVLTrojan/Generic.ASMalwS.34E77BC
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D244CED4
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Exploit.C4819506
McAfeeRDN/Generic Exploit
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallTROJ_GEN.R06BC0PKM21
AVGWin32:Malware-gen
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/TrojanDownloader.Agent.JRU?

MSIL/TrojanDownloader.Agent.JRU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment